ExamGecko
Question list
Search
Search

Related questions

Question 1121 - CISA discussion

Report
Export

Which of the following would be the GREATEST concern to an IS auditor when reviewing the outsourcing contract for an organization's cloud service provider?

A.
There is no change management process defined in the contract.
Answers
A.
There is no change management process defined in the contract.
B.
There are no procedures for incident escalation.
Answers
B.
There are no procedures for incident escalation.
C.
There is no dispute resolution process defined in the contract.
Answers
C.
There is no dispute resolution process defined in the contract.
D.
There is no right-to-audit clause defined in the contract.
Answers
D.
There is no right-to-audit clause defined in the contract.
Suggested answer: D

Explanation:

The absence of a right-to-audit clause in the outsourcing contract for a cloud service provider would be of greatest concern to an IS auditor1.This clause gives the client the right to audit the service provider's activities that are relevant to the services being provided1.It is crucial for ensuring that the service provider is complying with the terms of the contract and meeting the client's standards for performance, security, and other aspects1.Without this clause, the client may not be able to effectively monitor and manage risks associated with the outsourcing arrangement1.

Audit rights in outsourcing: certifications and third party reports

asked 18/09/2024
Philippe Chretien
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first